rtMedia for WordPress, BuddyPress and bbPress, 6fa535e572b66737c3d2bfee4afd1a6bb64ebce1
- CVE, Research URL
- Application
- Published on
- Dec 21, 2016
- Research Description
- rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.2.1 rtMedia for WordPress, BuddyPress and bbPress <= 4.2 - Arbitary File Upload The rtMedia for WordPress, BuddyPress and bbPress for WordPress is vulnerable to Direct file access in versions up to, and including, 4.2. This is due to the 'rtUploadAttachment.php' file preventing direct access to the the file. This makes it possible for unauthenticated attackers to access the file directly which triggers execution and lets unauthenticated users upload files.
- Affected versions
-
max 4.2.1.
- Status
-
vulnerable